Access Control Vulnerability in FreeScout Help Desk Software
CVE-2025-48473
What is CVE-2025-48473?
FreeScout, a self-hosted help desk software, had a significant access control vulnerability prior to version 1.8.179. This flaw allowed users to create conversations from messages in other conversations without appropriate visibility checks. Consequently, unauthorized users could access arbitrary messages from different mailboxes or conversations they were not meant to view. The oversight stemmed from a lack of validation against the 'show_only_assigned_conversations' setting, which is intended to restrict access. This issue was addressed in version 1.8.179 to enhance security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
freescout < 1.8.179
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
